Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Possible to strip domain from src_user/user field?

$
0
0
For Palo logs, the username is being extracted with the domain in front of it, i.e., `domain\user` To be CIM compliant, shouldn't the domain\ be removed so only the user is listed as a value? Is there a way to remove the domain\ from the user field extraction? Thx

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>